Privacy
Under the GDPR · last updated August 2026
1. Who is responsible
2. The short version
You can read every chart on this site without a cookie being set and without an account. We set cookies only for signed-in advertisers, and — only if you say yes — for Google Analytics and Google AdSense. The banners we sell ourselves work without cookies entirely.
3. Hosting and server logs
The site runs on a server operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, located in Frankfurt am Main. Each request is written to a log file with the IP address, timestamp, requested address, referrer and browser identification. This is technically necessary to run the site and to defend it against attack (Art. 6(1)(f) GDPR). Logs rotate daily and are deleted automatically after 14 days.
4. The banners we deliver ourselves
When a banner becomes visible on your screen we record the impression, because that is exactly what the advertiser pays for. We store the time, the page, and a visitor identifier — a SHA-256 hash of your IP address, your browser identification and the current date, of which only 24 characters are kept. The IP address itself is never stored, and because the date is part of the hash, the same visitor produces a different identifier tomorrow. Recognising someone across days is therefore impossible.
The only purposes are billing an impression once rather than twice (the same identifier counts once within 30 seconds) and attributing clicks correctly. The legal basis is our legitimate interest in billing correctly (Art. 6(1)(f) GDPR). The identifier and the page path are deleted after 90 days; only the counts an advertiser needs for their invoice remain.
The only purposes are billing an impression once rather than twice (the same identifier counts once within 30 seconds) and attributing clicks correctly. The legal basis is our legitimate interest in billing correctly (Art. 6(1)(f) GDPR). The identifier and the page path are deleted after 90 days; only the counts an advertiser needs for their invoice remain.
5. Cookies and local storage
dji_ads — a session cookie, only for signed-in advertisers, so an ad account stays signed in across pages. It expires after 30 days, is HttpOnly and is only transmitted over an encrypted connection (Art. 6(1)(b) GDPR).
dji_consent — your answer to the cookie question, stored in your browser's local storage so we do not ask again. It never leaves your browser.
dji_consent — your answer to the cookie question, stored in your browser's local storage so we do not ask again. It never leaves your browser.
6. Google Analytics and Google AdSense
Neither is loaded until you have agreed in the banner — before that, no connection to Google is made at all. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; a transfer to the United States is possible on the basis of the EU standard contractual clauses and the EU-US Data Privacy Framework. Google sets cookies and processes, among other things, your IP address, device and the pages you visit — in the case of AdSense in order to select and bill advertisements. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time with effect for the future:
7. Ad accounts and payments
For an ad account we store your email address, a name, a password hashed with scrypt, your billing details, your banners with their destination addresses, and your credit and spend (Art. 6(1)(b) GDPR). Payment is handled by Whop Inc., 700 N San Vicente Blvd, West Hollywood, CA 90069, USA. Card and payment data is processed there and never reaches our server; we receive only the payment reference and the amount. On a refund we send that same payment reference and amount back to Whop so the money can find its way home. Invoices and credit notes are kept for ten years under § 147 AO.
8. Email
Invoices, warnings that credit is running low, and password reset links are sent through a mail server operated by Strato AG, Otto-Ostrowski-Str. 7, 10249 Berlin, Germany. There is no newsletter and no marketing email.
9. Fonts and external content
Typefaces are downloaded when the site is built and served from our own server; visiting the site creates no connection to Google Fonts. Artist images come from publicly accessible Spotify data and are likewise stored on our own server.
10. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. An email to info@maximschunk.com is enough. You may also complain to a supervisory authority — ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.